A 6-lens hostile panel with adversarial verification confirmed 17 attacks that
would hold in a public takedown. All repaired: the MI contract now carries the
two base-fee floor-lapse windows (12,978,617-13,087,959 and
13,596,033-13,596,141) as explicit ruleset validation exceptions, so a stranger
implementing the written rules no longer halts where our own follower did; the
honesty boundary now states the full record of reject-on-disagreement including
the windows, and why the fact stays load-bearing; the independence claim is
bounded (upstream skeletons yes, AERE ruleset has one author in both forks, so
a common-author bug passes any differential gate by construction); the harness
verdict claims only what it measures, records engine identity via
web3_clientVersion on every run, refuses same-URL endpoint pairs, and prints
its NOT MEASURED block on every run; stage 4 names the live engine (upstream
parallel processing enabled by default, idling on empty blocks) and its
oracle's model limits; 'governed registry' became 'owner-controlled' with the
single-key fact stated. The panel also confirmed the import-proof doc claimed
a two-month validation history where six days is the truth; fixed.
Motivated by a real defect a from-genesis import proof found the same day: the
public patch set's loader bound key index 0 while its seal rule called it
unbound, rejecting a valid first anchor certificate that production accepts.
The model proves with z3 that under one shared index->address mapping,
'unbound never validates' is a theorem, and exhibits both divergence
directions: valid-rejected (liveness loss, the defect measured today) and
unvouched-accepted (safety loss, the silent one). Both proven impossible under
agreement. Six checks, each with the solver required to SAT the planted bad
world before the UNSAT proof counts. Engineering consequence stated: one
function, not two implementations of the same idea.
The governed on-chain registry (AereCryptoRegistry) maps every registered
post-quantum algorithm to a live verifier: measured 2026-08-15, all 5
algorithms (Falcon-512, Falcon-1024, ML-DSA-44, SLH-DSA-128s, SHAKE256)
resolve to the live NIST precompiles 0x0AE1..0x0AE5, status active, and the
registry contract itself bears code. So 'crypto agility' is not a slide: adding
a scheme or retiring one is a governed registry write, not a hard fork.
Negative control: a planted fake verifier address is caught. Read-only,
eth_call and eth_getCode only. Building this caught two of my own decode bugs
(wrong selector, wrong tuple word) before they became a false public claim,
which is what verification-before-publication is for.
Block-STM enters the kernel through the MachineInterface seam, not beside it. The
one guarantee, stated as a contract and proven: parallel execution produces the
byte-identical state root that serial execution produces, or the kernel refuses
it. The feared failure mode is a silent state divergence under contention, and
that is exactly what the negative control plants.
Run 2026-08-15 (WSL, Rust release build of parallel-executor):
- positive: harness reports 0 mismatches, parallel Block-STM == sequential on
all profiles, seeds, and thread counts 4/8/16.
- negative control: disable the validation phase (the mechanism that catches a
stale read and forces re-execution) and the harness reports MISMATCH on every
contended profile. So the oracle is load-bearing, not applause.
No throughput number is claimed; 8-10x is proven capacity while chain 2800
blocks are empty. Parallel execution is not put on mainnet in this stage; the
equality that would make that safe is proven, so the switch becomes a measured
decision. One coordinated activation if it ever changes an observable, the
discipline proven at block 14,050,000.
Execution proofs are an audit layer OVER the chain, never under it. For that
layer to mean anything, the claim chain must be continuous, and this tool
measures three properties from the live chain: linkage (each window's
prevStateRoot equals the previous window's postStateRoot and the chain's real
root before the first), no gaps or overlaps in the tiling, and anchoring (each
postStateRoot equals the header.stateRoot the chain actually published, so the
proof proves the committed state and not a parallel one). It reports proving
LAG as a first-class number, because lag is the cost curve of proving and
hiding it is the failure.
Run and measured 2026-08-15 against rpc.aere.network: an 8-window synthetic
chain built from live state roots verifies clean; four negative controls (gap,
overlap, linkage, anchor) each make the detector go red, and the anchor plant
is isolated on the last window so it trips the anchoring rule specifically,
not linkage. Read-only, installs nothing. Points at a claims file when a public
proof endpoint exists; the deprecated aggregator V1 stays fenced.
The kernel's first stage is not new infrastructure, it is a written contract
for the state-transition seam (pre_state, block) -> (post_state, receipts)
through StateView only, plus a harness that proves two independent clients
agree on the state root of real chain-2800 blocks, in both directions per the
D-150 rule (what was lost, not only what was added).
Run and measured 2026-08-15, from the two public endpoints (Besu at
rpc.aere.network, Nethermind at client2.aere.network): 24 blocks, 168 fields,
zero divergences. All four negative-control plants (value differs, block only
on one side, a lost field, a corrupted side) make the gate go red exactly
where planted. Installs nothing, three read-only RPC methods, runnable by
anyone. This makes "a second execution machine tomorrow" a mechanical slot,
not a promise.
Written and run against z3 4.16.0, exit 0, on 2026-08-15, the day the blocking
fork went live:
- anchor_blocking_quorum: past block 14,050,000 no anchor block finalizes with
fewer than K=3 distinct valid Falcon seals; the negative control that permits
2 seals is SAT (the violation is expressible), the property itself UNSAT.
- pqanchor_ceiling_monotonicity: the emergency ceiling can only LOWER the
effective threshold, never raise it, and K_eff always fits under the write
cap; a planted max()-instead-of-min() ceiling is SAT.
- registry_rotation_coverage: the registry schedule covers every anchor height
with exactly one registry, no gap and no overlap, and a seal is checked
against the registry active at the ANCHOR height; a planted schedule with a
gap is SAT.
These extend the existing SMT corpus toward end-to-end verifiability of the
consensus, one of the pieces the roadmap calls distinctive.
The public history carried kat/__pycache__/mlkem768_reference.cpython-314.pyc,
a compiled Python artifact embedding the operator's absolute local path. Text
secret scanners do not read compiled binaries, which is exactly how it slipped
through, and removing it from the tip would have left it reachable through the
old root commits. So this repository is republished from a single clean root.
This root also carries, from the previously unpublished line of work:
- corrected LICENSE year, LICENSING.md, VERIFY-POLICY.md, and
CITATIONS-UNRESOLVED.md remeasured 2026-08-11 (101 paths, README aligned)
- O-018: run_consensus_verification.py ran 19 of 29 models and reported PASS;
it now runs all 29, and computemarket_smt.py gains resolveByTimeout /
reclaimUnsettled cases plus a negative control
- O-006: the word 'audited' removed from next to Bouncy Castle, twice, after a
concurrent edit resurrected it
- O-014: prior art named and dated - Algorand's native falcon_verify shipped
about ten months before AERE's precompiles; the primacy claim is withdrawn
where it was implied
- bench/ scripts parametrized so they actually run for an outsider (the
earlier textual sanitization left $STAGING unexpanded inside Python strings)
- AIP-2/AIP-3 errata with measured figures, spec remeasurements at 2026-08-01,
and the spec-zk-stack retractions (owner is an operational key, not the
Foundation; 'maximally sound' withdrawn; aggregator V1 deprecated)
The redacted bench-host environment files from the sanitized line are kept
exactly as published; the unredacted local variants are not carried.